Privacy Policy
Effective date: [EFFECTIVE_DATE]
This document is a draft and should be reviewed by a qualified legal professional before production use.
1. Who we are
Tutor365 is a CRM/SaaS workspace for private tutors to manage schedules, students, lessons, payments, balances, and finance overviews. The service is operated by [LEGAL_ENTITY_NAME], a [LEGAL_ENTITY_TYPE] with registered address at [LEGAL_ADDRESS]. In this Privacy Policy, "Tutor365", "we", "us", and "our" refer to that operator.
Contact for privacy questions: [CONTACT_EMAIL]. Governing privacy jurisdiction placeholder: [JURISDICTION].
2. Scope of this policy
This Privacy Policy explains how we collect, use, store, disclose, and protect personal data when a visitor uses the public Tutor365 website, creates an account, logs in, uses the authenticated app, contacts us, or interacts with legal and authentication pages.
This policy should be read together with the Terms of Service and the Personal Data Processing Consent.
3. Roles and responsibility for tutor workspace data
The account owner controls the lesson, student, payment, balance, and note data that they enter into Tutor365. The account owner is responsible for making sure they have a lawful basis and, where required, permission to add personal data about students, parents, guardians, or other contacts to the service.
Tutor365 provides the technical workspace and processes account content to deliver the service, maintain security, synchronize data, provide support, and comply with applicable obligations.
4. Personal data we may collect
- Account data: name, email address, password hash, email verification status, account creation date, and account settings.
- Authentication and session data: session identifiers, CSRF tokens, password reset tokens, email verification tokens, login timestamps, device/browser information, IP-derived technical information, and active-session metadata.
- Workspace data entered by the user: student names, group names, lesson dates and times, subjects, topics, notes, contact details, payment status, balances, transaction notes, archive status, and finance summary inputs.
- Support and communication data: messages, email correspondence, troubleshooting details, and information needed to respond to a request.
- Technical data: IP address, user agent, browser language, referring URL, pages visited, error logs, server logs, security events, and synchronization metadata.
- Analytics data: page views, clicks, referrers, approximate technical identifiers, and usage events collected through analytics tools such as Yandex Metrika where enabled.
5. Data we do not intentionally request
Tutor365 is not designed to collect special categories of personal data, medical information, government identifiers, payment card numbers, or sensitive student records. Users should not enter unnecessary sensitive data into lesson notes, student profiles, or finance notes.
6. How we use personal data
- To create and maintain user accounts.
- To authenticate users, protect sessions, verify email addresses, reset passwords, and prevent unauthorized access.
- To store, display, synchronize, and back up calendar, student, lesson, payment, balance, finance, and settings data.
- To provide core app features such as recurring lessons, payment status, balance tracking, finance summaries, theme settings, and account deletion.
- To send service-related messages such as verification, password reset, security, support, and operational emails.
- To maintain security, detect abuse, investigate incidents, debug errors, and protect the service.
- To measure usage, understand product performance, and improve public and authenticated pages.
- To comply with legal obligations, enforce our Terms of Service, and respond to lawful requests.
7. Legal bases or processing grounds
The exact legal bases must be finalized for [JURISDICTION]. Depending on the applicable law, processing may be based on user consent, performance of a contract, legitimate interests such as service security and product operation, compliance with legal obligations, or other grounds allowed by applicable law.
Where consent is required, the user may withdraw consent by contacting [CONTACT_EMAIL] or using available account controls, subject to any processing that remains necessary for legal, security, or contractual reasons.
8. Cookies and local storage
Tutor365 uses cookies and browser storage to keep users signed in, protect requests, preserve interface preferences, and support app functionality. Authentication sessions are stored using protected cookies where technically possible. Browser storage may also be used for local preferences, draft state, and synchronization support.
Analytics tools may use cookies or similar technologies to understand traffic and interactions. Users can usually manage cookies through browser settings, but disabling essential cookies may prevent login or app functionality.
9. Processors and service providers
We may use service providers to host the service, authenticate users, send emails, store data, analyze usage, and provide technical infrastructure. Current placeholders include hosting provider [HOSTING_PROVIDER] and authentication provider [AUTH_PROVIDER].
Service providers should process personal data only as needed to provide their services to Tutor365 and subject to appropriate contractual, technical, and organizational safeguards.
10. Data sharing
We do not sell personal data. We may disclose personal data to service providers, legal or regulatory authorities, professional advisers, or successors in the event of a merger, restructuring, or transfer of the service, only where there is a valid reason and appropriate safeguards.
11. International transfers
Personal data may be processed in countries other than the user's country of residence if our hosting, authentication, analytics, support, or infrastructure providers operate there. Transfer mechanisms and required notices must be finalized for [JURISDICTION], [HOSTING_PROVIDER], and [AUTH_PROVIDER].
12. Data retention
Account and workspace data are retained while the account is active and as long as needed to provide the service. Users may delete their account through available account controls where implemented. Account deletion is intended to remove authentication data, sessions, and the user's stored calendar data, subject to backups, logs, legal obligations, security needs, and technical retention periods.
Security logs, support records, and analytics data may be retained for limited periods needed for security, troubleshooting, business records, or legal compliance. Exact retention periods must be finalized before production use.
13. Security
We use technical and organizational measures intended to protect personal data, including session protection, CSRF protection, password hashing, access controls, account-scoped data access, and operational safeguards. No online service can guarantee absolute security. Users should choose strong passwords, keep account credentials confidential, and contact us if they suspect unauthorized access.
14. User rights
Depending on [JURISDICTION], users may have rights to access, correct, delete, export, restrict, object to, or withdraw consent for the processing of personal data. Users may contact [CONTACT_EMAIL] to make a request. We may need to verify identity before responding.
15. Children's and student data
Tutor365 is intended for tutors and account owners, not for direct use by children. If a tutor enters data about a minor student, the tutor is responsible for ensuring that they have the required legal basis, authority, and notices or consents from the student, parent, or guardian under applicable law.
16. Changes to this policy
We may update this Privacy Policy to reflect changes in the service, law, providers, or business practices. The effective date will be updated when a new version is published. Material changes may be communicated through the website, app, or email where appropriate.
17. Contact
Operator: [LEGAL_ENTITY_NAME], [LEGAL_ENTITY_TYPE], [LEGAL_ADDRESS]. Privacy contact: [CONTACT_EMAIL].